US seizes domains linked to China's Flax Typhoon hackers, disrupts two cyber tools
Synopsis
Key Takeaways
The US Justice Department and the FBI have seized internet domains used by suspected Chinese state-sponsored hackers to target critical infrastructure and computer networks across the United States and abroad, disrupting two cyber tools — Microscan and FishHub — used for vulnerability scanning and targeted attacks. The operation, announced on Thursday, 8 October 2026, was authorised by a federal court in Pennsylvania and marks the second publicly confirmed US disruption of the same hacking network.
The Operation and Its Targets
The seized domains were linked to Integrity Technology Group, a China-based company with government contracts, allegedly operating as a contractor for Flax Typhoon — a Chinese state-sponsored cyber group that US authorities have associated with attacks on government, commercial, and critical infrastructure networks worldwide. A seizure warrant issued on 6 October by US Magistrate Judge Maureen P. Kelly in the Western District of Pennsylvania authorised the seizure of seven domain names.
Targets of the hacking operation reportedly included a power company in South Carolina, a multinational non-governmental organisation, airports in Japan and Poland, Taiwanese natural gas and electricity companies, and two universities in Taiwan.
How the Two Tools Worked
According to court documents, Microscan was developed by Integrity Tech to identify vulnerabilities in computer systems that could subsequently be exploited by its clients. The company allegedly deployed a botnet — comprising internet-connected devices infected with a variant of Mirai malware — to conduct large-scale scanning operations, with hackers accessing the tool through one of the seized domains.
The second tool, FishHub, was allegedly used in spear-phishing attacks designed to compromise targeted networks. Once initial access was obtained, FishHub could download additional malicious software enabling unauthorised remote access or extract specific files and transmit them to servers controlled by Integrity Tech. Approximately 20 Taiwanese universities were confirmed as victims of FishHub-related activity, according to the Justice Department.
What US Officials Said
Assistant Attorney General for National Security John A. Eisenberg issued a pointed warning: 'The United States will not allow China or its proxies to operate against United States interests with impunity in cyberspace.' He said the Justice Department would continue using its investigative and enforcement powers to disrupt the group's operations.
US Attorney Troy Rivetti for the Western District of Pennsylvania said the operation demonstrated Washington's determination to disrupt Chinese-linked cyber activity. 'These state-sponsored hackers continue to aggressively target and access networks and systems throughout the world in an effort to identify and steal files and otherwise exploit victims' vulnerabilities,' Rivetti said.
FBI Cyber Division Assistant Director Brett Leatherman emphasised the contractor model Beijing allegedly uses to scale its operations. 'The PRC relies on contractor and enabling companies to expand the reach and scale of its malicious cyber activity,' he said.
Background and Pattern
This is the second publicly announced US disruption of Integrity Tech's cyber infrastructure. In September 2024, the Justice Department announced the takedown of a Mirai malware botnet associated with the same company, which had compromised more than 200,000 consumer devices in the United States and other countries. The recurrence underscores what US officials describe as a persistent, contractor-driven Chinese cyber campaign that adapts and reconstitutes after each disruption.
This comes amid an intensifying pattern of US-China friction in cyberspace, with federal agencies having previously attributed multiple infrastructure intrusions — including attacks on telecoms and water utilities — to Beijing-linked actors. Analysts note that targeting civilian infrastructure such as airports, power companies, and universities signals an intelligence-gathering and pre-positioning strategy rather than purely destructive intent.
What Comes Next
The Justice Department has indicated it will continue enforcement actions against entities supporting Chinese state cyber operations. The seizures neutralise the specific domain infrastructure used by Microscan and FishHub, but investigators have not disclosed whether arrests or indictments are forthcoming. Governments in Japan, Poland, and Taiwan — whose infrastructure was among the confirmed targets — are expected to be briefed by US counterparts.